clickhouse-connect is vulnerable to Exposure of Sensitive System Information
15
Low Risk
Affected versions of this package may expose sensitive system information, as the HTTPDriver returns the Clickhouse server IP and port number in the error exception.
You are affected if you are using a vulnerable version of the package.
clickhouse-connect is vulnerable to Exposure of Sensitive System Information in versions 0.4.0 - 0.7.13.
Upgrade clickhouse-connect to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant